SurrealDB 3.1.5 patches five flaws; lead is a HIGH file read
SurrealDB shipped 3.1.5 on June 19, closing five same-day GitHub advisories — including arbitrary file read via DEFINE ANALYZER mapper at CVSS 7.7. No CVE IDs assigned yet.
SurrealDB shipped 3.1.5 on June 19, closing five same-day GitHub advisories — including arbitrary file read via DEFINE ANALYZER mapper at CVSS 7.7. No CVE IDs assigned yet.
Researcher Bob Diachenko found an open attacker server holding plaintext admin and SSL VPN credentials for 73,932 FortiGate appliances across 194 countries. CISA issued reset guidance June 18.
F5 shipped NGINX 1.31.2 and 1.30.3 on June 17 fixing a use-after-free in the HTTP/3 module, a heap overflow in proxy_v2/grpc, and a buffer overread in charset.
Microsoft documents the @mastra npm takeover: 142 packages republished in 88 minutes on June 17 with the easy-day-js typosquat, dropping a cross-platform Node.js infostealer.
Second Cisco Catalyst SD-WAN Manager zero-day in two weeks. CVE-2026-20262 is an arbitrary file write under exploitation; CISA gave agencies until June 29 to patch.
CISA added CVE-2026-48907 to KEV on June 16 — an unauth profile-import chain in the JCE Joomla extension that lets attackers upload and execute PHP. Patch in JCE 2.9.99.5.
CISA added CVE-2026-54420 — a CVSS 8.5 symlink-following bug in the LiteSpeed cPanel plugin — to KEV on June 15. Federal patch deadline: June 18.
Google's June 8 Stable Channel pushes 149.0.7827.102/.103 for an actively exploited V8 out-of-bounds read/write. CISA added the CVE to KEV the next day.
Unauthenticated root RCE in Ivanti Sentry. CVSS 10.0. Shadowserver sees exploitation a day after the patch. CISA KEV deadline is June 14.